The invention relates to an
attack trapping system based on
firmware simulation. The
attack trapping system comprises the following steps: (1) obtaining and analyzing
firmware; (2) for the
firmware information obtained in the step (1), using a QEMU simulator to simulate target firmware through a
system-level
simulation technology; (3) on the basis of the step (2), constructing a
honeypot system, deploying a high-interaction
honeypot system based on an SSH proxy protocol in a
virtualization environment, and performing information configuration; and (4) on the basis of the step (3), performing
attack behavior capture, monitoring various attack behavior characteristics of the equipment in real time in the
honeypot, and capturing information such as an attack initiating way of an attacker andthe like. According to the invention, analog
simulation is carried out on the firmware through the QEMU simulator, and the honeypot environment based on the SSH protocol is deployed by using the
virtualization technology, so that various attack behaviors for the equipment can be effectively monitored in real time, malicious attacks can be captured, and a more efficient and complete system securityprotection system can be constructed.